• rose56@lemmy.zip
    link
    fedilink
    English
    arrow-up
    5
    ·
    13 hours ago

    Im on fedora and I have installed through dnf, no updates with the dnf update… should I wait?

    • gigachad@piefed.social
      link
      fedilink
      English
      arrow-up
      8
      arrow-down
      1
      ·
      12 hours ago

      I depends a bit on your threat model. If you have Jellyfin exposed to the internet I would shut it down immediately. If you are running locally and rely on it, let it run maybe? If behind a tailnet or some other VPN, I would deactivate it as well. If it is an Axios like vulnerability it may be possible your secrets are in danger, dependent on how well they are secured. Not a security expert, but I would handle this a little more conservative…

      • somehacker@lemmy.world
        link
        fedilink
        English
        arrow-up
        10
        ·
        11 hours ago

        No need to shut it down if it’s not exposed to the internet. Tailnet/VPN is fine.

        If it’s a supply chain compromise shutting it down wouldn’t matter. The damage is already done.